August 5, 2026
Able Finance handles money, and money leaves a trail. This policy sets out exactly what we record about you, why each piece of it is necessary, who else sees it, and what you can ask us to do with it. Where we are required by law to keep or disclose something, we say so plainly rather than leaving it implied.
In this policy, "Able", "we", "our" and "us" mean [Able Finance legal entity name], registered at [registered address] under company number [number].
Able operates through more than one company. The Able company that provides your account or card is the controller of your personal information for that product, and it is the company named in the terms and conditions you accepted. We tell you which one it is when you apply, and you can check it at any time in your account settings.
Parts of our service are delivered with regulated partners -- including our card issuing partner, whose cards are issued in Singapore, along with our banking and payment processing partners. Where a partner is a controller of your information in its own right, its own privacy notice applies alongside this one, and we identify that partner to you at the point it becomes relevant.
Some products and processes have their own notice with more detail -- for example our cookie policy, and the notices shown when you complete identity verification or apply for a specific product. We also show short, plain explanations inside the app at the moment you use a feature for the first time, so you can see what is being collected before you decide.
We may publish this policy in languages other than English. If there is a conflict between versions, the English version is the one that applies.
if you switch location services on, we use your device location to help confirm that a card transaction is happening where you are, which reduces false declines and helps detect fraud. You can turn this off at any time in your device or app settings, and doing so does not stop you using your account.
We also generate new information by analysing what we already hold. This includes your customer risk rating, fraud and transaction risk scores, spending and activity patterns used to spot anomalies, eligibility indicators showing which products we can offer you, and -- where you have not opted out -- segments used to make our communications relevant.
We do not ask for special category data such as health, religious or political information. If a document you upload happens to reveal it -- a place of birth or a religious title on an identity page, for example -- we process only what is necessary to verify the document. Biometric data is special category data, and we handle it under the specific grounds set out in section 5.
Sometimes we have to ask you about someone else -- a joint account holder, a beneficial owner or director of your business, a person who sent you money, or a family member whose funds are involved in a transaction. We ask only because anti-money-laundering and sanctions rules require it.
If you give us personal information about another person, you confirm that you are entitled to do so and that you have shown them this policy. If you would rather we contacted them directly, tell us and we will.
Purpose: Opening your account
What This Involves: Verifying your identity, checking eligibility, and deciding whether we can offer you an account or card.
Purpose: Running the service
What This Involves: Processing top-ups, payments and card transactions, confirming payee details before a transfer leaves, producing statements, issuing and replacing cards, and applying account limits and controls.
Purpose: Financial crime prevention
What This Involves: Screening, ongoing monitoring, investigation and reporting, as described in section 6.
Purpose: Fraud and security
What This Involves: Detecting unusual activity, protecting accounts from unauthorised access, authenticating you, and investigating suspected fraud or misuse.
Purpose: Support and disputes
What This Involves: Answering questions, handling complaints, and pursuing chargebacks and dispute claims on your behalf.
Purpose: Spending insights
What This Involves: Showing you where your money goes, categorising transactions, and flagging activity you may want to check.
Purpose: Improving the product
What This Involves: Understanding how features are used, fixing faults, testing improvements, and developing and testing the models described in section 7.
Purpose: Protecting our business
What This Involves: Managing risk, recovering amounts you owe us including any negative balance, enforcing our terms, defending legal claims, and dealing with harmful or unlawful use of the service.
Purpose: Legal and regulatory
What This Involves: Meeting obligations to regulators, tax authorities, courts, card networks and our partner institutions.
Purpose: Marketing
What This Involves: Sending product news and offers in line with your choices -- see section 11.
Where data protection law such as the UK and EU GDPR applies to you, we rely on the following grounds:
Ground: Performance of a contract
When We Rely On It: Opening and operating your account, processing your payments, and providing support.
Ground: Legal obligation
When We Rely On It: Identity verification, record keeping, sanctions screening, transaction monitoring, suspicious activity reporting and tax reporting.
Ground: Legitimate interests
When We Rely On It: Fraud prevention, network and information security, product improvement, debt recovery, managing risk across our business, and direct marketing to existing customers where the law permits. We balance these against your rights, and you may object -- see section 17.
Ground: Substantial public interest
When We Rely On It: Processing biometric data to verify identity, and processing limited special category or criminal-offence data where anti-money-laundering, sanctions or fraud prevention law requires it.
Ground: Vital interests
When We Rely On It: Rare cases where using your information is necessary to protect someone's life -- for example, sharing details with emergency services when we have reason to believe there is an immediate risk to you or another person.
Ground: Consent
When We Rely On It: Optional marketing, non-essential cookies, location services, and biometric checks where your jurisdiction requires separate consent. You can withdraw consent at any time, and doing so does not affect processing that already took place.
We are required to know who our customers are and to monitor how accounts are used. This is not optional for us, and it is the reason for much of what we collect.
To keep our controls effective, we cannot publish every detail of how they work -- explaining a rule precisely would help people evade it. We will always tell you as much as we lawfully can about a decision that affects you.
Some decisions are made by our systems without a person reviewing them first, because payments happen in seconds. These include:
We use statistical models, machine learning and -- in some places -- generative AI. Specifically
We do not use your personal information to train third-party general-purpose AI models, and our suppliers are contractually barred from using it to train theirs.
Where an automated decision has a legal or similarly significant effect on you, you can ask for it to be reviewed by a person, explain your circumstances, and contest the outcome. Write to us at the address in section 21.
When you pay with an Able card, the transaction is processed through our card issuing partner, its processor and the relevant card network before it reaches the merchant's bank. Each of them receives the data needed to authorise, clear and settle the payment -- including the card reference, amount, currency, merchant details and location. Those parties act as controllers under their own rules and privacy notices. Cards can be used wherever the relevant card network is accepted, subject to the country, currency and merchant-category restrictions in section 6.
When you send a transfer, payment rules require us to include certain details about you -- typically your name and account identifier -- so the receiving institution can process it. When someone pays you, we give the sender confirmation of the account details, which may include your name. This is standard across all payment institutions and is not something either of us can opt out of.
Before a transfer leaves your account, we may check the name you entered against the name on the destination account and tell you whether it matches. This protects you from misdirected payments and from impersonation scams.
If money reaches your account in error, we may share your details with the sending institution or the sender so the payment can be recovered. If you send money in error, we will ask the receiving institution to do the same for you.
Where you add a card to a mobile wallet, the wallet provider processes the data needed to create and manage that token. We store full card numbers only in protected, tokenised form, and our staff cannot retrieve them.
If you connect an account you hold at another institution, we receive the data you authorise -- typically balances, transactions and account details -- and use it only for the purpose you connected it for. Your permission lasts until you withdraw it, and you can disconnect a linked account at any time in your settings. Where another provider connects to your Able account with your permission, we share the data that permission covers, and you can withdraw it the same way.
Where the law allows us to market to existing customers, we will send you news about Able products by email, push notification and in-app message unless you tell us not to. Where the law requires your consent first, we ask for it before sending anything.
We personalise these messages using how you use the service, so they are relevant rather than generic. You can object to that profiling separately from objecting to the marketing itself.
To stop marketing, use the privacy settings in the app, click unsubscribe in any email, or write to us. Two things to know: opting out does not stop service messages -- security alerts, statement notices, terms changes and scam warnings, which we have to send you -- and you may still see general product information inside the app.
We do not pass your details to other organisations for their own marketing without your permission.
We do not sell your personal information. We share it only where it is needed to deliver the service, meet a legal duty, or protect against fraud
A consequence worth knowing. If we or a fraud prevention agency record that you present a fraud or money laundering risk, that record may be visible to other organisations. It can lead to other companies refusing you services, financing or employment, and those agencies may keep the record for several years. If you believe such a record is wrong, contact us and we will investigate.
We vet every company before sharing personal information with it, assess the controls it has in place, and bind it contractually to use the data only for the purpose we specify. We require every third party with whom we share your personal information -- including the partners, suppliers and any parent, subsidiary or related entities described above -- to provide the same or equal protection of your personal information as set out in this policy.
We combine data across many customers to produce statistics -- spending trends, product usage, forecasting and regulatory reporting. Once combined, the result cannot be linked back to you as an individual, and we may share it internally or with third parties. Anonymised data is no longer personal information, so the rights in section 17 do not apply to it.
Able operates across several regions, and our partners and suppliers do too. Your information may be stored or accessed in countries other than the one you live in, including [list your primary hosting regions]. International payments necessarily involve sending data to institutions in the destination country.
Wherever your information is handled, we protect it to the standard set out in this policy. Where the law of your country restricts sending personal information abroad, we only do so using a lawful transfer method -- for example, sending it to a country the relevant authority has approved, or putting a contract in place that binds the recipient to protect your data to the same standard. You can ask us which method applies to you by writing to us.
Type: Strictly necessary
What It Does: Keeps you signed in, protects sessions, balances load and blocks abuse. These cannot be switched off.
Type: Preferences
What It Does: Remembers language, currency display and interface choices.
Type: Analytics
What It Does: Tells us which pages and features are used, and where people get stuck. Set only with your consent where consent is required.
Type: Marketing
What It Does: Measures campaign performance and limits repeat advertising. Off unless you opt in.
Our marketing emails contain small tracking pixels that tell us whether the email was delivered, opened and clicked, along with your IP address, browser and email client type. We use this to measure campaign performance. Turning off marketing emails turns this off too.
You can change your choices at any time through the cookie settings link in our footer, and through your browser controls. Blocking necessary cookies will stop parts of the service from working.
We apply technical and organisational measures appropriate to the sensitivity of financial data:
No system can be made immune to every risk, and we do not claim otherwise -- data can also be intercepted on its way to us, which is outside our control.
Category: Identity and due diligence records
Retention Period: At least five years after your relationship with us ends, and generally no more than [seven] years, unless a regulator or applicable law requires longer.
Category: Transaction and card records
Retention Period: At least five years from the date of the transaction.
Category: Financial crime investigations and reports
Retention Period: For the period set by the relevant law, which may exceed the periods above.
Category: Support correspondence, call recordings and complaints
Retention Period: Up to six years after the matter is closed.
Category: Applications we declined
Retention Period: Kept for a limited period to record the decision and prevent repeat or fraudulent applications, then deleted.
Category: Biometric data
Retention Period: Deleted or irreversibly anonymised once verification is complete and any legally required record of the check has been made.
Category: Website and analytics data
Retention Period: Typically up to 24 months, or less where you withdraw consent.
We may keep information longer where it is needed for an ongoing or potential legal claim, an investigation, or a regulatory request. Fraud prevention agencies set their own retention periods, which can run to several years. When a period ends, we delete the information or anonymise it so it can no longer identify you.
Right: Be informed
What It Means In Practice: To know how we use your information -- through this policy, the notices that sit alongside it, and the explanations shown in the app.
Right: Access
What It Means In Practice: A copy of the personal information we hold about you. We cannot give you information about other people, anything tied to an ongoing fraud or criminal investigation, or our legal advice.
Right: Correction
What It Means In Practice: To have inaccurate or incomplete information fixed. We may need to verify the new details first.
Right: Deletion
What It Means In Practice: To have information erased where there is no longer a good reason to hold it. As a regulated firm we must keep certain records even after your account closes, and we will always tell you when that applies.
Right: Portability
What It Means In Practice: A copy of the data you gave us, in a structured, machine-readable format.
Right: Restriction
What It Means In Practice: To have us pause our use of your information while we check its accuracy, or while we consider an objection you have raised.
Right: Objection
What It Means In Practice: To object to processing based on legitimate interests, including profiling. If we have an overriding reason we will say so -- and if the objection concerns data we need to run your account, we may have to close it.
Right: Withdraw consent
What It Means In Practice: At any time, for anything based on consent, without affecting what was lawful before.
Right: Human review
What It Means In Practice: Of a significant automated decision, with the chance to explain your position and contest the outcome.
Right: Opt out of marketing
What It Means In Practice: Through app settings, the unsubscribe link, or by telling us.
Right: Complain
What It Means In Practice: To us first, and to your data protection authority if our answer does not satisfy you.
Whether a right applies depends on where you live, the information involved, and why we hold it. We will tell you which of these applies to your request rather than declining without explanation.
Able's services are for adults. We do not offer accounts or cards to anyone under 18, and we do not knowingly collect information from children. If you believe a minor has given us personal information, contact us and we will delete it, subject to any record-keeping obligation that applies. If we ever offer a product for under-18s, it will have its own notice written for that audience, and a parent or guardian will approve the account.
We update this policy when our services, partners or legal obligations change. The "last updated" date at the top shows the current version. If a change materially affects how we use your information, we will notify you by email or in the app before it takes effect, and where the law requires it we will ask for your consent.
For any question about this policy, or to exercise a right:
If you are not satisfied with our response, you can complain to the data protection authority in your country. [Insert the lead supervisory authority and its contact details.]